Although blockchain-based digital services promise trust, accountability, and transparency, multiple paradoxes between blockchains and GDPR have been highlighted in the recent literature. Some of the recent literature also proposed possible solutions to these paradoxes. This article aims to conduct a systematic literature review on GDPR compliant blockchains and synthesize the findings. In particular, the goal was to identify 1) the GDPR articles that have been explored in prior literature; 2) the relevant research domains that have been explored, and 3) the research gaps. Our findings synthesized that the blockchains relevant GDPR articles can be categorized into six major groups, namely data deletion and modification (Article 16, 17, and 18), protection by design by default (Article 25), responsibilities of controllers and processors (Article 24, 26, and 28), consent management (Article 7), data processing principles and lawfulness (Article 5,6 and 12), and territorial scope (Article 3). We also found seven research domains where GDPR compliant blockchains have been discussed, which include IoT, financial data, healthcare, personal identity, online data, information governance, and smart city. From our analysis, we have identified a few key research gaps and present a future research direction.
翻译:虽然基于供应链的数字服务承诺信任、问责和透明度,但最近的文献中也强调了供应链与GDPR之间的多重矛盾,最近的一些文献也对这些矛盾提出了可能的解决方案。这一条的目的是对符合GDP的供应链进行系统的文献审查,并综合调查结果。特别是,其目标是确定1)以前文献中探讨的GDPR条款;2)已经探讨的相关研究领域;3)研究差距。我们的调查结果综合表明,有关GDP链与GDPR条款的多重矛盾可分为六大类,即数据删除和修改(第16、17和18条)、设定的默认保护(第25条)、控制者和处理者的责任(第24、26和28条)、同意管理(第7条)、数据处理原则和合法性(第5、6和12条)以及领土范围(第3条)。我们还发现,在七个研究领域,对GDP链的兼容性进行了讨论,其中包括IoT、金融数据、保健、个人身份、在线数据、信息治理和智能城市。我们通过分析发现了几个关键研究差距,并提出了未来研究方向。